CVE-2018-9381

In gatts_process_read_by_type_req of gatt_sr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*

History

18 Dec 2024, 19:39

Type Values Removed Values Added
CPE cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*
First Time Google
Google android
References () https://source.android.com/docs/security/bulletin/pixel/2018-06-01 - () https://source.android.com/docs/security/bulletin/pixel/2018-06-01 - Patch, Vendor Advisory
Summary
  • (es) En gatts_process_read_by_type_req de gatt_sr.c, existe una posible divulgación de información debido a datos no inicializados. Esto podría provocar una divulgación de información remota sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación.

02 Dec 2024, 22:15

Type Values Removed Values Added
CWE CWE-908
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

02 Dec 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-02 20:15

Updated : 2024-12-18 19:39


NVD link : CVE-2018-9381

Mitre link : CVE-2018-9381

CVE.ORG link : CVE-2018-9381


JSON object : View

Products Affected

google

  • android
CWE
CWE-908

Use of Uninitialized Resource